Amendments to PA data breach notification law will take effect soon

Recent amendments to Pennsylvania’s data breach law -- the Breach of Personal Information Notification Act – will take effect May 3. The amendments were enacted in November.

Originally enacted in 2006, the Act provides for the security of computerized data and requires notification to Pennsylvania residents whose personal information data was, or may have been, disclosed due to a breach of the security of an entity’s system. 

In amending the Act, the state legislature took steps similar to other states’ data breach notification statutes and expanded the definition of “personal information.”  The expanded definition that will take effect May 3 includes medical and health information, and a user name or email address in combination with a password or security questions and answers that would permit access to an online account. These are in addition to the categories of personal information that all states regulate – for example, name in combination with a Social Security Number, driver license number or state identification card number, or financial account or debit/credit card number in combination with an access code, password, or security code that would allow access to the account. 

The Act currently requires notification when a “discovery” has been made that there was a security breach. As amended, the Act will require notification when a “determination” of a breach has been made. The new standard will be more entity-friendly than the prior standard because it takes into account an entity’s need to investigate whether a breach has occurred before it is obligated to provide notice. A “discovery” occurs when the entity has “[t]he knowledge of or  reasonable suspicion” that a breach has occurred. A “determination” occurs when the entity has “[a] verification or reasonable certainty” that a breach has occurred.

A “breach of the security of the system” is defined as “unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information maintained by the entity as part of a database of personal information regarding multiple individuals . . ..”

The Act currently applies to state agencies, but the amendments will expand the Act to cover “State Agency Contractors” as well. The amended Act includes specific timelines and requirements for notification by state agencies, state agency contractors, public schools, counties, and municipalities when a determination of breach has been made. For example, state agencies and their contractors will have seven business days to notify individuals after the breach determination, and they must also notify the Office of the Attorney General by the same deadline.  Counties, public schools, and municipalities will have seven days to notify individuals, and three days to notify the district attorney’s office in the County in which the breach occurred. Other governmental entities are not required to notify the AG’s office.

The amendments include provisions that require state agencies and state agency contractors to protect the personal information of the Commonwealth that they maintain, store, or manage. These protective measures include encryption, “or other appropriate” security measures to protect the information from unauthorized access or acquisition, either when being transmitted or when “at rest.”  The amendments also require the development of policies and procedures to protect such data. With regard to storing personal information on behalf of the Commonwealth, the amended Act requires state agencies and their contractors to “develop a policy to govern reasonably proper storage of the personal information” with the goal of reducing the risk of future breaches of the security of the systems. The amendments even dictate the considerations that state agencies and their contractors must take into account when developing those policies and procedures, including best practices considered by the federal government and the Commonwealth.

Other changes in the amended Act include the following:

  • Entities will be allowed to provide email notice to the affected individuals when the breach involves a user name or email address in combination with a password, or a security question and answer that would permit access to an online account. Email notice will be permitted under these circumstances if the email directs the individual to promptly change his or her password and security question or answer, or to take other appropriate steps to protect the online account with the entity or other online accounts involving the same personal information.
  • Entities will be deemed to comply with the Pennsylvania law if they are in compliance with the privacy rule of the federal Health Insurance Portability and Accountability Act and the Health Information Technology for Economic and Clinical Health Act.
  • State agencies and their contractors will be deemed to comply with the Pennsylvania law if they are in compliance with the notification requirements established by their primary state or functional federal regulators.

In sum, the amendments will bring Pennsylvania’s data breach notification scheme into line with other states that are seeking to hold entities responsible for the protection of consumer personal information and personal health information. It will hold state agencies (including public schools) and their contractors to stricter notification requirements and a higher degree of responsibility when maintaining, storing, and managing personal information. On a more positive note, the amendments will allow entities to investigate and make a “determination” that a breach has occurred before their notification obligation takes effect, they will be able to provide certain notifications by email, and they may be exempt if they are in compliance with other specified regulatory obligations.

  • Lauren Godfrey wearing a gray blazer over a white top, accessorized with a cross necklace and drop earrings, arms crossed, posed against a light blue and white geometric background.
    Partner

    Lauren guides clients through data security incidents, leading initial assessments and coordinating forensic and remediation efforts to contain, investigate, and resolve issues. She helps clients develop privacy, incident ...

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek